Threats Tagged 'pyinstaller'
View all threats tagged with 'pyinstaller'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'pyinstaller'
Click on any threat for detailed analysis and mitigation recommendations
A Python-based Malware-as-a-Service builder enables operators to generate customized Windows infostealer executables. The system comprises a builder component and an embedded payload, using Nuitka or PyInstaller compilation to evade detection. The builder features automatic dependency installation, webhook configuration with XOR and Base64 encoding, and multiple compilation backends. The payload targets Chromium and Firefox browsers, extracting credentials, cookies, and credit card data. It harvests Wi-Fi passwords, Discord tokens, and Roblox session cookies while employing anti-analysis techniques including debugger detection, VM process blacklisting, disk size checks, and timing evasion. Persistence is established through registry Run keys and scheduled tasks. All stolen data is packaged into in-memory ZIP archives and exfiltrated via attacker-controlled webhooks, following a scalable affiliate model. Join the discussion | AlienVault OTX General | 09/28/2026, 10:51:14 UTC Added: 09/28/2026, 13:47:52 UTC |
An analysis of threat clusters, dubbed UNG0801 or Operation IconCat, targeting Israeli organizations. The actors use socially engineered phishing lures in Hebrew, exploiting antivirus icon spoofing from well-known vendors like SentinelOne and Check Point. Two distinct infection chains were identified, both utilizing AV-themed decoys dropped by malicious Word and PDF documents. The first campaign deploys a PyInstaller-based implant called PYTRIC, capable of system-wide wipes and backup deletion. The second campaign uses a Rust-based implant named RUSTRIC, focusing on antivirus enumeration and system information gathering. Both campaigns share similar tactics but differ in their ultimate objectives, with the first aimed at destruction and the second at espionage. Join the discussion | AlienVault OTX General | 12/22/2025, 17:06:57 UTC Added: 12/23/2025, 09:21:49 UTC |
Inf0s3c Stealer is a sophisticated Python-based malware designed to collect system information and user data. It systematically gathers host identifiers, CPU information, network configuration, and captures screenshots. The malware enumerates running processes, generates directory views, and compiles stolen data into a password-protected archive for exfiltration. It employs various techniques for persistence, including injection into Discord and Windows Startup manipulation. The stealer targets sensitive information such as passwords, cookies, browsing history, and cryptocurrency wallets. It also implements anti-VM checks and can self-delete after execution. The analysis reveals similarities with other malware projects, suggesting potential for rapid iteration and wider distribution. Join the discussion | AlienVault OTX General | 09/03/2025, 05:35:37 UTC Added: 09/03/2025, 06:17:49 UTC |
Showing 1 to 3 of 3 results